The Art of Systems Architecting, Second Edition

APIs are one of the most powerful vehicles for value exchange in the digital economy. Matt McLarty and his co-author Tiffany Wang have provided a simple yet compelling way of building APIs to maximize this value exchange. In this conversation with Matt, Setu Kulkarni explores integrating security in the 3 “ways of the API”. For the first way, the “Unbundling Way”, they conclude that organizations need to develop an API visibility strategy: CISO & System Architects to build out a baseline API inventory & network and implement tooling to update the API inventory & network organically. For the second way, the “Outside In Way”, they conclude that API exposition should be guided by customer use cases & abuse cases and that API security should be a central consideration for production readiness checks for APIs. For the third way, the “Ecosystem Way”, they conclude that organizations should set up voluntary disclosure frameworks for their API and data security practices so that the internal software development teams measures up to those standards and external partners & consumers develop the confidence they need to integrate/use your public APIs.

Read this episode's accompanying blog: https://www.whitehatsec.com/blog/the-ways-of-the-api-a-useful-pattern-to-apply-to-api-security/

Links for further reading & listening:

  • https://hbr.org/2021/04/apis-arent-just-for-tech-companies
  • https://www.forbes.com/sites/forbesbusinessdevelopmentcouncil/2021/03/05/de-risking-business-partnerships-in-an-application-driven-economy/
  • https://www.amazon.com/Art-Systems-Architecting-Second/dp/0849304407
  • https://www.oreilly.com/library/view/securing-microservice-apis/9781492027140/
  • https://podbay.fm/p/radio-mulesoft/e/1598593948